diff --git a/modules/anagrafiche/ajax/select.php b/modules/anagrafiche/ajax/select.php index ae612368d..6e6a1a38f 100755 --- a/modules/anagrafiche/ajax/select.php +++ b/modules/anagrafiche/ajax/select.php @@ -430,10 +430,13 @@ $user = auth_osm()->getUser(); $id_azienda = setting('Azienda predefinita'); - $query = "SELECT * FROM (SELECT '0' AS id, 'Sede legale' AS `nome_sede`, CONCAT_WS(' - ', \"".tr('Sede legale')."\" , (SELECT CONCAT (`citta`, IF(`indirizzo`!='',CONCAT(' (', `indirizzo`, ')'), ''),' (', `ragione_sociale`,')') FROM `an_anagrafiche` |where|)) AS descrizione UNION SELECT `id`, `nome_sede`, CONCAT_WS(' - ', `nome_sede`, CONCAT(`citta`, IF(`indirizzo`!='',CONCAT(' (', `indirizzo`, ')'), '')) ) FROM `an_sedi` |where| ORDER BY `nome_sede`) AS tab |filter| ORDER BY descrizione"; + $query = "SELECT * FROM (SELECT '0' AS id, 'Sede legale' AS `nome_sede`, CONCAT_WS(' - ', \"".tr('Sede legale')."\" , (SELECT CONCAT (`citta`, IF(`indirizzo`!='',CONCAT(' (', `indirizzo`, ')'), ''),' (', `ragione_sociale`,')') FROM `an_anagrafiche` |where|)) AS descrizione UNION SELECT `id`, `nome_sede`, CONCAT_WS(' - ', `nome_sede`, CONCAT(`citta`, IF(`indirizzo`!='',CONCAT(' (', `indirizzo`, ')'), '')) ) FROM `an_sedi` |where_sedi| ORDER BY `nome_sede`) AS tab |filter| ORDER BY descrizione"; $where[] = '`id`='.prepare($id_azienda); $where[] = 'deleted_at IS NULL'; + $where_sedi[] = '`id_anagrafica`='.prepare($id_azienda); + $where_sedi[] = 'deleted_at IS NULL'; + $query = str_replace('|where_sedi|', 'WHERE '.implode(' AND ', $where_sedi), $query); // filtro in base alle sedi abilitate dell'utente if ($user->gruppo != 'Amministratori') { diff --git a/tests/AnagraficheCompanyLocationsSelectorTest.php b/tests/AnagraficheCompanyLocationsSelectorTest.php new file mode 100644 index 000000000..c7ccf0c7b --- /dev/null +++ b/tests/AnagraficheCompanyLocationsSelectorTest.php @@ -0,0 +1,19 @@ +.*?)case 'referenti':/s", $source, $matches); + + $selector = $matches['selector'] ?? ''; + + $this->assertStringContainsString('FROM `an_sedi` |where_sedi|', $selector); + $this->assertStringContainsString("\$where_sedi[] = '`id_anagrafica`='.prepare(\$id_azienda);", $selector); + $this->assertStringContainsString("\$where_sedi[] = 'deleted_at IS NULL';", $selector); + $this->assertStringContainsString("str_replace('|where_sedi|', 'WHERE '.implode(' AND ', \$where_sedi), \$query)", $selector); + } +}